US2006041669A1PendingUtilityA1

Securing web services

Assignee: LUCENT TECHNOLOGIES INCPriority: May 19, 2004Filed: May 19, 2004Published: Feb 23, 2006
Est. expiryMay 19, 2024(expired)· nominal 20-yr term from priority
H04L 63/0807H04L 63/08H04L 63/10
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A scalable policy-based Web Services security architecture that incorporates a combination of authentication with service discovery, evaluation of access policies, and capturing the result of this process in a signed, security token, thus, allowing efficient processing for each service request in a secure manner. A method for securing a Web Service comprises discovering the Web Service in response to a service request and determining an access policy for the Web Service separately from the actual service based on the service request.

Claims

exact text as granted — not AI-modified
1 . A method for securing a Web Service, the method comprising: 
 discovering the Web Service in response to a service request; and    determining an access policy for the Web Service separately from the actual service based on the service request.    
   
   
       2 . A method for securing a Web Service, the method comprising: 
 sending one or more invocations to the Web Service after discovering the Web Service.    
   
   
       3 . A method, as set forth in  claim 1 , wherein determining the access policy for the Web Service separately from the actual service based on the service request further comprises: 
 using a pre-computed policy.    
   
   
       4 . A method, as set forth in  claim 3 , wherein using a pre-computed policy further comprises: 
 evaluating access policies for the Web Service to determine identity and access policy information; and    encoding the identity and access policy information in a security token based on said pre-computed policy.    
   
   
       5 . A method, as set forth in  claim 4 , wherein encoding the identity and access policy information in a security token further comprises: 
 using a signed security token with each subsequent service request.    
   
   
       6 . A computer readable medium comprising programming instructions for a web server coupled to a network for serving service requests, the web server linked to a plurality of clients, the programming instructions comprising: 
 discovering the Web Service in response to a service request; and    determining an access policy for the Web Service separately from the actual service based on the service request.    
   
   
       7 . The computer readable medium according to  claim 6 , further comprising instructions for: 
 sending one or more invocations to the Web Service after discovering the web service.    
   
   
       8 . The computer readable medium according to  claim 6 , further comprising instructions for: 
 using a pre-computed policy.    
   
   
       9 . The computer readable medium according to  claim 7 , further comprising instructions for: 
 evaluating access policies for the Web Service to determine identity and access policy information; and    encoding the identity and access policy information in a security token based on said pre-computed policy.    
   
   
       10 . The computer readable medium according to  claim 9 , further comprising instructions for: 
 using a signed security token with each subsequent service request.    
   
   
       11 . A web server for serving Web Services to a plurality of clients linked via a network therewith, the web server comprising: 
 an interface coupled to a cache for storing identity and access policy information;    an access controller including a policy engine to evaluate access policies and encode its decision in a security token; and    a module for securing a Web Service based on an access policy determined for the Web Service separately from the actual service based on a service request.    
   
   
       12 . A web server according to  claim 11 , wherein the module to discover the Web Service in response to the service request.  
   
   
       13 . A web server according to  claim 11 , wherein the module to send one or more invocations to the Web Service after discovering the Web Service.  
   
   
       14 . A web server according to  claim 11 , wherein the module to use a pre-computed policy.  
   
   
       15 . A web server according to  claim 11 , wherein the module to capture the security token in a signed security token for use with each subsequent service request.  
   
   
       16 . A system for securing a Web Service, the system comprising: 
 a client that sends a service request for a Web Service over a network; and    a web server coupled to said network to serve the Web Service across different administrative domains based on a pre-computed policy.    
   
   
       17 . A system for securing a Web Service; wherein the web server further comprises: 
 an interface coupled to a cache for storing identity and access policy information.    
   
   
       18 . A system for securing a Web Service, wherein the web server further comprises: 
 an access controller including a policy engine to evaluate access policies and encode its decision in a security token.    
   
   
       19 . A system for securing a Web Service, wherein the web server further comprises: 
 a module for securing a Web Service based on an access policy determined for the Web Service separately from the actual service based on a service request.    
   
   
       20 . A system for securing a Web Service, as set forth in  claim 19 , wherein the module to discover the Web Service in response to the service request.  
   
   
       21 . A method on a server linked to a network of a plurality of clients, the method comprising: 
 receiving a service request from a client;    using a first access controller element to discover a service in response to the service request; and    using a second access controller element which separates access control enforcement from the actual service based on the service request.    
   
   
       22 . A method, as set forth in  claim 21 , wherein using a first access controller element to discover a service further comprises: 
 performing authentication of the service request;    calculating access policy for the service; and    caching authentication and access policy evaluations.    
   
   
       23 . A method, as set forth in  claim 21 , wherein caching authentication and access policy evaluations further comprises: 
 encoding identity and access policy information in a signed access token; and    detecting a service invocation.    
   
   
       24 . A method, as set forth in  claim 23 , wherein detecting a service invocation further comprises: 
 in response to a service invocation, passing the signed access token to an access controller; and    reusing the authentication and access policy calculations.    
   
   
       25 . A method as set forth in  claim 24 , wherein reusing the authentication and access policy calculations further comprises: 
 enabling use of a standard Web Service across different administrative domains.

Join the waitlist — get patent alerts

Track US2006041669A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.